<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 14:47:45 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15219</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15219</link>
      <description>bdu:2025-15219</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15219</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0941 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0941</link>
      <description>certfr-2025-avi-0941</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0941</guid>
    </item>
    <item>
      <title>EUVD-2026-256564</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-256564</link>
      <description>EUVD-2026-256564</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-256564</guid>
    </item>
    <item>
      <title>fkie_cve-2025-62518</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-62518</link>
      <description>&lt;p&gt;astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-62518</guid>
    </item>
    <item>
      <title>GHSA-j5gw-2vrg-8fgx — astral-tokio-tar Vulnerable to PAX Header Desynchronization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j5gw-2vrg-8fgx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: astral-tokio-tar, crates.io: tokio-tar&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Versions of `astral-tokio-tar` prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers.&lt;/p&gt;
&lt;p&gt;This vulnerability was disclosed to multiple Rust tar parsers, all derived from the original `async-tar` fork of `tar-rs`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerability Description&lt;/p&gt;
&lt;p&gt;The vulnerability stems from inconsistent handling of PAX extended headers versus ustar headers when determining file data boundaries. Specifically:&lt;/p&gt;
&lt;p&gt;1. **PAX header** correctly specifies the file size (e.g., `size=1048576`)
2. **ustar header** incorrectly specifies zero size (`size=000000000000`)
3. **tokio-tar** advances the stream position based on the ustar size (0 bytes)
4. **Inner content** is then interpreted as legitimate outer archive entries&lt;/p&gt;
&lt;p&gt;### Attack Mechanism&lt;/p&gt;
&lt;p&gt;When a TAR file contains:&lt;/p&gt;
&lt;p&gt;- An outer entry with PAX `size=N` but ustar `size=0`
- File data that begins with valid TAR header structures
- The parser treats inner content as additional outer entries&lt;/p&gt;
&lt;p&gt;This creates a **header/data desynchronization** where the parser&amp;#39;s position becomes misaligned with actual file boundaries.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;```rust
// Vulnerable: Uses ust…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: astral-tokio-tar, crates.io: tokio-tar&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Versions of `astral-tokio-tar` prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers.&lt;/p&gt;
&lt;p&gt;This vulnerability was disclosed to multiple Rust tar parsers, all derived from the original `async-tar` fork of `tar-rs`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerability Description&lt;/p&gt;
&lt;p&gt;The vulnerability stems from inconsistent handling of PAX extended headers versus ustar headers when determining file data boundaries. Specifically:&lt;/p&gt;
&lt;p&gt;1. **PAX header** correctly specifies the file size (e.g., `size=1048576`)
2. **ustar header** incorrectly specifies zero size (`size=000000000000`)
3. **tokio-tar** advances the stream position based on the ustar size (0 bytes)
4. **Inner content** is then interpreted as legitimate outer archive entries&lt;/p&gt;
&lt;p&gt;### Attack Mechanism&lt;/p&gt;
&lt;p&gt;When a TAR file contains:&lt;/p&gt;
&lt;p&gt;- An outer entry with PAX `size=N` but ustar `size=0`
- File data that begins with valid TAR header structures
- The parser treats inner content as additional outer entries&lt;/p&gt;
&lt;p&gt;This creates a **header/data desynchronization** where the parser&amp;#39;s position becomes misaligned with actual file boundaries.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;```rust
// Vulnerable: Uses ust…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j5gw-2vrg-8fgx</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-62518 — astral-tokio-tar Vulnerable to PAX Header Desynchronization</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-62518</link>
      <description>msrc_CVE-2025-62518</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-62518</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15658-1 — python311-uv-0.9.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15658-1</link>
      <description>&lt;p&gt;python311-uv-0.9.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-uv-0.9.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15658-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2025-0110 — astral-tokio-tar Vulnerable to PAX Header Desynchronization</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2025-0110</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: astral-tokio-tar&lt;/p&gt;
&lt;p&gt;Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing
vulnerability that allows attackers to smuggle additional archive entries by
exploiting inconsistent PAX/ustar header handling. When processing archives with
PAX-extended headers containing size overrides, the parser incorrectly advances
stream position based on ustar header size (often zero) instead of the
PAX-specified size, causing it to interpret file content as legitimate tar
headers.&lt;/p&gt;
&lt;p&gt;This vulnerability was disclosed to multiple Rust tar parsers, all derived from
the original async-tar fork of tar-rs.&lt;/p&gt;
&lt;p&gt;For additional information see
[Edera&amp;#39;s blog post](https://edera.dev/stories/tarmageddon).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: astral-tokio-tar&lt;/p&gt;
&lt;p&gt;Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing
vulnerability that allows attackers to smuggle additional archive entries by
exploiting inconsistent PAX/ustar header handling. When processing archives with
PAX-extended headers containing size overrides, the parser incorrectly advances
stream position based on ustar header size (often zero) instead of the
PAX-specified size, causing it to interpret file content as legitimate tar
headers.&lt;/p&gt;
&lt;p&gt;This vulnerability was disclosed to multiple Rust tar parsers, all derived from
the original async-tar fork of tar-rs.&lt;/p&gt;
&lt;p&gt;For additional information see
[Edera&amp;#39;s blog post](https://edera.dev/stories/tarmageddon).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2025-0110</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20077-1 — Security update for python-uv</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20077-1</link>
      <description>&lt;p&gt;Security update for python-uv&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-uv&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20077-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-62518</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-62518</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: rust-astral-tokio-tar, Ubuntu:26.04:LTS: rust-astral-tokio-tar&lt;/p&gt;
&lt;p&gt;astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: rust-astral-tokio-tar, Ubuntu:26.04:LTS: rust-astral-tokio-tar&lt;/p&gt;
&lt;p&gt;astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-62518</guid>
    </item>
  </channel>
</rss>
